PT-2026-98850 · Kitty · Kitty
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
kitty versions 0.40.0 through 0.48.x
Description
An out-of-bounds write exists in the natural width branch of the text sizing protocol. The
screen handle multicell command() function in kitty/screen.c appends each codepoint of a grapheme cluster using lc.chars[lc.count++] = ch without performing a capacity check. Because lc is declared as a four-element char type array via the RAII ListOfChars macro, an OSC 66 escape code containing a grapheme cluster longer than four codepoints writes beyond the buffer. If the cluster is preceded by a sequence causing an intermediate flush, the buffer is migrated to the heap by ensure space for chars(), and the write occurs past the heap allocation. This leads to the termination of the kitty process, including all associated windows, tabs, and child processes.Recommendations
Update to version 0.49.0 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kitty